Dimension scores are derived from public data and fields; weighted into the composite. Reference only.
Fiddling 科技工作室 was founded in 2023 and positions itself as a security engineering studio focused on cybersecurity, engineering practice, and Forward Deployed Engineering. It is not a standardized SaaS security product, but rather a consulting and project delivery service built around specific problems, with an emphasis on “turning exploration into engineering that is runnable, deliverable, and reviewable.”
In terms of protection and assessment, the website explicitly mentions Web, Android, and iOS penetration testing, red team/blue team exercises, code audits, and security assessments, with attention to real attack paths and remediation approaches that are acceptable to the business. For SDLC, its approach is to embed security checks, standards, tools, training, and post-project reviews into the development process, turning security from a one-off test into a team habit. Its FDE work is more field-delivery oriented, covering goal decomposition, prototyping, integration, debugging, documentation, and the clarification of boundaries. For AI Agent and automation, it emphasizes starting from real workflows, integrating with common collaboration platforms and existing tools, and building small systems that are observable and maintainable.
The website does not disclose standard pricing, packages, or payment methods. Its collaboration process starts with discussing goals, scope, constraints, and blockers, then breaking down boundaries, and finally confirming fees, timelines, deliverables, and follow-up support. As a result, it is better suited to project-based or custom-quoted engagements. Before procurement, clients should clearly define the authorized scope, delivery standards, and acceptance criteria.
The main advantage is that its service descriptions are practical, emphasizing authorization boundaries, risk assumptions, restricted areas, remediation priorities, and review materials, making it suitable for security assessments and process-building work that need to be implemented in the real world. The downside is that public information is limited: there is no visible compliance certification, qualifications, team size, customer cases, SLA, or continuous alerting platform information. Enterprise procurement teams will need additional due diligence.
It is suitable for teams preparing to launch, needing to re-understand their attack surface, wanting to build a lightweight security baseline, or aiming to apply AI Agents/automation to specific workflows. Access from China, network stability, and payment methods are not stated in the main content, so they should be considered unknown. If you need a mature vendor, compliance backing, or large-scale continuous operations, you may want to compare domestic alternatives such as 长亭科技, 知道创宇, 安恒信息, 绿盟科技, and 奇安信.
⚠ This review is compiled from public sources and does not constitute a purchase recommendation. Verify all facts on the vendor's official site. Verify on fiddling.work official site.
fiddling.work is an China Security provider. TG4G tracks its product information, with monthly pricing from $42.00, an overall rating of 5.0/10, and a China-accessibility score of China direct-connect friendly. Click "Visit Official Site" to reach fiddling.work directly.